Security at ELASA
Last Updated: August 13, 2026
Security is foundational to everything we build at ELASA. Our platform handles sensitive agency and policyholder information every day, and we treat protecting that data as a core product requirement — not an afterthought. ELASA is built and operated with controls that align closely to SOC 2 standards across our infrastructure, development workflows, and personnel practices.
Where we are on SOC 2
We have not yet completed a formal SOC 2 audit — it is on our roadmap. What matters today is that the safeguards, processes, and oversight behind that certification are already in effect. As a lean, fast-moving team, we have chosen to prioritize robust security implementation over the substantial time and cost of formal certification, which lets us stay focused on the product while still meeting the security standards our customers expect.
Practices in effect today
- Encryption in transit. All traffic between your browser, our application, and our APIs is encrypted with TLS.
- Credential protection. Account passwords are stored only as salted, one-way hashes. Carrier portal credentials you connect are encrypted at rest and are never exposed in plaintext.
- Two-factor authentication. 2FA is available to protect account access.
- Payment security. Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Card numbers never touch ELASA servers.
- Hardened cloud infrastructure. ELASA runs on Amazon Web Services with least-privilege access controls, and we apply defense-in-depth measures such as a strict Content Security Policy and bot protection on public-facing forms.
- Data minimization. We collect only what the platform needs to quote and service policies, and we never sell your data. See our Privacy Policy for details.
Security reviews
If you are conducting a security review, evaluating ELASA for your agency, or have questions about any of our policies or practices, we are happy to share additional documentation and engage directly. Reach us at support@elasa.ai and we will respond promptly.